This text reflects the marketing website as built. It needs the operator’s details and a review before adoption for a public commercial launch.
Scope and operator
This draft policy covers the ThreatLens AI marketing website. It does not describe an operational threat-analysis service. Before adopting it, the operator should add its legal identity, location, applicable rights procedures, actual providers, and retention periods.
Information visitors provide
Demo and contact forms ask for business contact details and a message. With no submission service configured, the website does not transmit those form entries. A draft email link opens your email application; you control whether to send it. Please avoid including passwords or confidential security incidents in a general enquiry.
Demo requests and contact submissions
If a submission service is connected, entries may be processed to answer enquiries and arrange product discussions. The operator must identify the provider, lawful processing basis where applicable, recipients, and actual retention period before enabling collection.
Website usage and hosting
The site does not install an analytics library. Hosting and network providers may process operational information such as IP addresses and request logs. The operator should document actual hosting providers, purposes, and log retention before public launch.
Cookies and analytics
The website stores a theme preference in local storage when you choose light or dark mode. It does not currently set application tracking cookies or use analytics cookies. Hosting access controls may use separate platform mechanisms; see the hosting provider’s policy where relevant.
Service providers and international processing
The website’s operator must disclose the providers used for hosting, email, forms, and any later analytics. Processing locations and international-transfer safeguards depend on those choices; no particular safeguards are claimed by this template.
Data retention
Form values remain in the current browser form until navigation or reload; the application does not deliberately persist them. Theme preference remains until you remove it. Any server-side enquiry or hosting-log retention must be defined by the operator and disclosed here.
Security
Security measures should reflect the data and processing involved. This marketing website cannot guarantee confidentiality or eliminate security incidents. The Security page distinguishes intended product principles from current functionality.
Future security-sensitive product submissions
Future threat-analysis inputs may contain personal data, message content, attachments, credentials, or confidential business information. This website does not collect or analyze those inputs. Product-specific handling, provider use, retention, and user controls must be explained before such functionality is introduced.
User rights and choices
Depending on applicable law and the actual processing, visitors may have rights relating to access, correction, deletion, objection, or restriction. Contact the operator to discuss a request. A public launch needs a defined request-handling process and the relevant regulator information where required.
Children’s privacy
The marketing website is intended for a business audience and is not designed to solicit children’s personal information. Future education use cases will require additional safeguards and appropriate agreements before any student data is processed.
Changes and contact
Review this policy when processing changes. General enquiries can be directed to hello@example.com; security concerns can be directed to security@example.com. These addresses are placeholders until real mailboxes are configured.
Contact: hello@example.com